Versitygw
A versitygw S3 gateway for swamp, read over its admin API and its S3 API. Read-only.
One model type, @dataverket/versitygw/gateway. health checks the S3 endpoint's health path: reachable, TLS verified, latency. accounts lists every account with its role and POSIX ids, and drops the secret key the admin API returns in clear before anything is recorded. buckets lists every bucket and its owner. bucketSettings reads each bucket's versioning, policy, ACL, object lock, ownership controls, CORS and tags over the S3 API. inventory does all of that in one execution and tags every record with one id, and check applies rules to the records of one inventory: bucket owner missing or not the account of the same name, an account owning nothing, a role outside the allowed set, versioning without object lock, lock without versioning, a default retention mode outside the allowed set, a bucket anyone may read.
The same type reads a Ceph radosgw through its admin ops API (backend: rgw) or any S3 endpoint with one key pair (backend: s3); the bucket settings and the rules over them are plain S3 and the same everywhere.
versitygw has no read-only admin role, so every admin call signs with the root key pair, from exactly one source: a file of NAME=value lines read at call time, swamp's environment, or the pair as values from vault expressions, so the definition stores only the reference. Signing is SigV4 by aws4fetch; errors are the gateway's S3 error codes. Written against versitygw v1.8.0.
Global Arguments
| Argument | Type | Description |
|---|---|---|
| backend | enum | versitygw: accounts and buckets over its admin API. rgw: a Ceph radosgw, accounts and buckets over the |
| adminUrl | string | Base URL of the admin API, e.g. http://localhost:7071, or http://host:8000/admin for rgw. May end in a path prefix. Not used by the s3 backend |
| s3Url | string | Base URL of the S3 API, e.g. https://s3.example.org:443 |
| region | string | The region the gateway was started with; it rejects any other |
| caFile? | string | PEM file of the CA that signed the gateway's certificate, when it is not in the system store; a relative path is taken from the repository root |
| healthPath | string | The path given to versitygw's --health option. Other backends have none: give / and the answer counts |
| rootKeyFile? | string | File of NAME=value lines holding the root key pair, read at call time. |
| rootKeyEnv | boolean | Read the root key pair from swamp's environment, e.g. under a secret |
| rootAccessKey? | string | The root access key as a value, e.g. ${{ vault.get("<vault>", "<key>") }}; |
| rootSecretKey? | string | The root secret key as a value, supplied like rootAccessKey and always with it |
| accessKeyName | string | Variable holding the root access key, in the file or the environment |
| secretKeyName | string | Variable holding the root secret key, in the file or the environment |
| Argument | Type | Description |
|---|---|---|
| buckets? | array | Buckets to read; every bucket on the gateway when omitted |
| Argument | Type | Description |
|---|---|---|
| inventoryId? | string | The inventory to check; the latest inventory record's id when omitted |
| rules | array | Rules to apply. By default every rule but versioning-enabled, which a gateway meant to hold no versioned |
| allowedRoles | array | Account roles the account-role rule accepts |
| allowedLockModes | array | Default retention modes the lock-mode rule accepts. COMPLIANCE can be shortened by nobody until it |
| failOnFindings | boolean | Fail the method, after recording the result, when anything is found |
Resources
- Has README or module doc2/2earned
- README has a code example1/1earned
- README is substantive1/1earned
- Most symbols documented1/1earned
- No slow types (deprecated)1/1earned
- Dependencies pass trust audit2/2earned
- Has description1/1earned
- Platform support declared (or universal)2/2earned
- License declared1/1earned
- Verified public repository2/2earned